Approvals, signatures and wallet drainers
This is the mechanism behind most crypto theft. It takes fifteen minutes to understand and then protects you permanently.
Why approvals exist
A smart contract cannot take your tokens without permission. So before a swap, you grant the contract permission to spend that token. That grant is the approval, it is a separate transaction, and it usually persists forever with no limit unless you change it.
Why that becomes dangerous
Two ways. Either you approve a malicious contract directly, which then drains you immediately. Or you approved a legitimate contract months ago, that contract is later exploited, and your approval is still live.
The signature types worth recognising
The five minute habit
- Go to revoke.cash, or the token approvals tab on your chain's block explorer.
- Paste your address to review without even connecting.
- Look at every live approval. Anything you do not recognise or no longer use should go.
- Revoke them. Each revoke is a transaction and costs gas.
- Repeat every few months and immediately after using anything new.
Use a wallet that shows you the outcome
Rabby and Phantom both simulate a transaction and show the resulting balance change before you approve. If a signature would move a token you did not intend to spend, they say so. That single feature stops the overwhelming majority of drainer attacks.
BEFORE YOU MOVE ON
Common questions
What is a Permit signature?
A gasless off chain signature that grants a contract permission to spend your tokens. It looks like a harmless message request because there is no transaction and no fee, which is exactly why drainers use it.
How often should I revoke approvals?
Every few months, and immediately after interacting with any new protocol. It takes about five minutes and it is the highest value security habit in crypto.
Risk warning: crypto is highly volatile and largely unregulated. You can lose everything you put in. Nothing here is financial, investment or tax advice.
